Fedora Account System
Red Hat Associate
Red Hat Customer
An OS command injection vulnerability exists in noobaa-core within the src/util/os_utils.js file. The set_hostname function uses a template literal to interpolate the hostname parameter directly into a shell command executed via exec(). Because the input is not sanitized, an attacker can use shell metacharacters (e.g., semicolons or backticks) to execute arbitrary commands. This endpoint is exposed via the cluster_internal_api.set_hostname_internal RPC method. Exploitation requires a valid administrative auth_token. A successful attack allows for arbitrary command execution as the noob user (UID 10001) within the container, which can lead to full container compromise.